CVE-2009-1384 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-1384): pam_krb5 2.2.14 through 2.3.4, as used in Red Hat Enterprise Linux (RHEL) 5, generates different password prompts depending on whether the user account exists, which allows remote attackers to enumerate valid usernames.
I'm not sure about the versioning, BUT even if I'm wrong, this bug has it's use to remind you to remove older, vulnerable versions <3.12 from tree.
the red hat pam_krb5 and ours (from Russ Allbery) have a different codebase AFAIK. But on the other hand it doesn't hurt to clean up old pam_krb5 releases. Therefore -> fixed. g, mueli
Thanks! I had in mind that there was something up with pam_krb5; now I had a look: our package is called "sys-auth/pam_krb5" in portage, but in fact it is pam-krb5 (note the hyphon/underscore); the redhat package is the "real" pam_krb5.